Skip to main content

Skills neste repositório

yanacuti1121/Yana-AI - Página 13

O SkillsMP coletou 1.566 skills de yanacuti1121/Yana-AI. Abra uma skill para revisar a origem e os detalhes.

yanacuti1121/Yana-AI

Mostrando 40 de 1.566 skills coletadas.

ocupação
Analistas de segurança da informação
descrição

Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, building detection rules for evasion tactics,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query patterns

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective DLL injection, WMI persistence, and…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk. Activates for requests…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17), abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs. Uses pandas for behavioral analytics and statistical baselines. Use when investigating…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltration, privilege abuse, and unauthorized…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests targeting service accounts with SPNs for offline password cracking.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account spray activity, remote service execution,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process creation, command-line arguments, and parent-child relationships to identify suspicious LOLBin execution patterns.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32 via process telemetry, Sigma rules, and parent-child process analysis

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702. The analyst correlates task creation with suspicious parent processes,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines using ICS-aware IDS and…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communications in industrial control systems. It addresses function code monitoring, register range validation, timing analysis, unauthorized client detection, and deep packet inspection for…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning activity.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB and LDAP signing enforcement across the domain, and detecting…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly detection. Covers access token theft, refresh token replay,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns in Splunk and Elastic SIEM

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect and prevent QR code phishing (quishing) attacks that bypass traditional email security by embedding malicious URLs in QR code images within emails.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics. Identifies mass file modification patterns, abnormal entropy spikes in written data, and suspicious process behavior…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance scanning, and staging behavior. Uses network detection tools…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques.…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google Cloud Functions) through event source poisoning, malicious layer injection, runtime command execution, and IAM privilege escalation via function…

Idioma do texto original: inglês

atualizado
Mostrando 40 de 1.566 skills coletadas.